SV-239874r682908_rule
V-239874
SRG-NET-000075-IDPS-00060
CASA-IP-000050
CAT II
10
Enable logging for connection events.
Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Access Control Policy. The Access Control Policy page appears.
Step 2: Click the edit icon next to the access control policy you want to configure. The access control policy editor appears.
Step 3: Click the edit icon next to a rule to edit. Select a logging option either log at Beginning and End of Connection or log at End of Connection. Select the Syslog check box.
Step 4: Click Save.
---------------------------------------------------
Enable logging for Intrusion events.
Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Intrusion Policy >> Intrusion Policy. The Intrusion Policy page appears.
Step 2: Click Advanced Setting. The Advanced Settings page appears.
Step 3: If Syslog Alerting under External Responses is enabled, click Edit. If the configuration is disabled, click Enabled, then click Edit. The Syslog Alerting page appears.
Step 4: In the Logging Hosts field, enter the remote access IP address you want to specify as logging host.
Step 5: Click Save.
Verify logging for connection events is enabled.
Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Access Control Policy. The Access Control Policy page appears.
Step 2: Click the edit icon next to the access control policy you want to view. The access control policy editor appears.
Step 3: Click the edit icon next to a rule to view. Verify a logging option has been selected. Verify the Syslog check box has been selected.
---------------------------------------------------
Verify logging for Intrusion events is enabled.
Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Intrusion Policy >> Intrusion Policy. The Intrusion Policy page appears.
Step 2: Click Advanced Setting. The Advanced Settings page appears.
Step 3: Verify that Syslog Alerting under External Responses is enabled.
If the Cisco ASA is not configured to produce log records containing information to establish when the events occurred, this is a finding.
V-239874
False
CASA-IP-000050
Verify logging for connection events is enabled.
Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Access Control Policy. The Access Control Policy page appears.
Step 2: Click the edit icon next to the access control policy you want to view. The access control policy editor appears.
Step 3: Click the edit icon next to a rule to view. Verify a logging option has been selected. Verify the Syslog check box has been selected.
---------------------------------------------------
Verify logging for Intrusion events is enabled.
Step 1: Navigate to Configuration >> ASA Firepower Configuration >> Policies >> Intrusion Policy >> Intrusion Policy. The Intrusion Policy page appears.
Step 2: Click Advanced Setting. The Advanced Settings page appears.
Step 3: Verify that Syslog Alerting under External Responses is enabled.
If the Cisco ASA is not configured to produce log records containing information to establish when the events occurred, this is a finding.
M
5341